In today’s highly interconnected world, data lies at the heart of our operations, powering our initiatives, linking our members, and enabling our shared achievements. Prioritizing data protection goes beyond mere legal compliance; it represents both an ethical responsibility and a strategic benefit in order to maintain the trust of our members, partners, and stakeholders.
Data protection laws are quite complex, constantly evolving and highly specific to individual circumstances and jurisdictions. For any specific legal questions, interpretations, or compliance requirements, particularly concerning your local laws or cross-border transfers, you must consult with qualified legal professionals. Nevertheless, we aim to provide you with at least a few basic principles that apply to all national groups. You can also find more detailed information in the Data Protection Handbook.
The aim of data protection is to guarantee that individuals’ personal data is managed in a responsible, transparent, and secure manner. The collection, storage, and use of personal information have become essential across both public and private sector activities. Data protection laws are designed to protect individuals against misuse, unauthorized access, or exploitation of their personal data, while upholding their fundamental right to privacy.
Personal data is any information relating to an identified or identifiable natural person. This can include but is not limited to:
Names, addresses, ID numbers;
Email addresses and phone numbers;
IP addresses;
Photos and video recordings;
Information about physical, physiological, genetic, mental, economic, cultural, or social identity.
An identifiable person is someone who can be directly or indirectly identified through this data.
Processing refers to any activity carried out on personal data, whether by automated means or otherwise. This includes, but is not limited to:
Collecting;
Recording;
Organising (which includes even viewing and sorting personal data);
Storing;
Altering;
Retrieving;
Deleting or destroying.
The General Data Protection Regulation (GDPR) applies to any organisation that processes the personal data of individuals within the EU, including associations such as ELSA. As ELSA operates throughout Europe and interacts with students, members, speakers, and partners, the GDPR is applicable at various levels of the organisation—from the International Board of ELSA to its National and Local Groups. In addition, there are of course other legal bases in national legislation, some of which either go beyond the GDPR or adopt different approaches.
In this instance, please check also the guidance on data protection and privacy policies in the Officers’ Portal.
As explained, personal data means any information relating to an identified or identifiable natural person - the data subject. Data subjects are natural persons that are the only beneficiaries of data protection regulations; in practice e.g. board or team members or participants to events or projects.
Any person to whom personal data is disclosed is a recipient. This can be a natural or legal person, public authority, agency, or another body, whether a third party or not; in practice e.g. an OC, a hotel, restaurant or partner or another ELSA group itself.
A (joint) controller is the entity responsible for ensuring that personal data is processed in compliance with the Regulation; in practice ELSA groups.
A (sub-)processor acts under the instructions of the controller or another processor only, by processing personal data on behalf of the controller or another processor; in practice a hotel (processor) and its IT-service-provider (sub-processor).
A third party refers to any natural or legal person other than the data subject, the controller, the processor, or individuals authorised to process personal data under the direct authority of the controller or processor; in practice anyone who is involved in the processing of data.
The data protection principles form the foundation of the Regulation’s approach to safeguarding personal data. They are intended to ensure that data is handled in a responsible and ethical way, protecting individual privacy while still enabling organisations to make effective use of information. These principles not only guide organisations in their data handling practices but also establish clear rights and protections for individuals regarding their personal data. By following these principles, we can build trust, ensure legal compliance, and reduce the risk of misuse or data breaches.
1. Lawfulness, Fairness and Transparency
Data must be processed in a lawful, fair, and transparent manner. This ensures that individuals are properly informed about how their personal data is used, and that consent is obtained where required.
2. Purpose Limitation
Personal data should only be collected for clear, specific, and legitimate purposes and must not be used in any manner that is incompatible with those original purposes. This principle helps prevent data from being used for unforeseen or unauthorised activities.
3. Data Minimisation
Only the minimum amount of personal data necessary to achieve the intended purpose should be collected and processed. This reduces the risk associated with holding excessive or irrelevant data.
4. Accuracy
Personal data must be accurate and kept up to date. Any incorrect information should be corrected without undue delay to ensure that decisions are not based on inaccurate data.
5. Storage Limitation
Personal data should not be retained for longer than is necessary for the purpose for which it was collected. Once it is no longer needed, it must be securely deleted or anonymised.
6. Integrity and Confidentiality
Data must be processed in a secure manner, protecting it against unauthorised access, loss, or destruction. This is ensured through appropriate technical and organisational measures that safeguard confidentiality and integrity.
A clear organisational strategy is essential for providing direction, using resources efficiently, and achieving goals effectively. In particular, a data protection strategy plays a key role in ensuring compliance with legal requirements, protecting sensitive information, and strengthening trust with stakeholders, especially members.
Such a strategy helps ensure compliance with regulations like the GDPR, reducing the risk of fines and legal consequences. It also strengthens protection against cyber threats, hacking, and accidental data loss by putting appropriate security measures in place.
In addition, it supports trust and reputation by reassuring members, participants, officers, and partners that their data is handled responsibly. It contributes to continuity and risk management by including backup systems and recovery plans that help maintain operations in case of incidents such as system failures or cyberattacks.
A data protection strategy also improves data governance by clearly defining how data is accessed, stored, and deleted, preventing unnecessary accumulation of information. It ensures that security measures evolve in response to new and emerging cyber threats.
Furthermore, it empowers officers by providing training and clear guidance, helping to reduce human error, which is a common cause of data breaches. Finally, it supports the fulfilment of legal and contractual obligations, particularly when working with third parties, by ensuring that data is managed in line with required standards.
You can find examples of the steps that are essential for an effective data protection strategy in the Data Protection Handbook. If, in addition to this, you require further assistance with drafting or revising your data protection strategy, please feel free to reach out to dataprotection@elsa.org.
Even if you have a working Data protection strategy, it will only be effective if it is actually put into practice. For this to happen, everyone involved needs to be aware of the framework and implications, which is why board members, team members, officers and organising committees need to be trained. You can achieve this by offering short, interactive workshops on specific data protection scenarios or Q&A sessions, as well as providing accessible data protection factsheets – subject to your national legislation – so that the knowledge conveyed in them can be put into practice straight away.
A ROPA is a formal document offering a detailed overview of how personal data is processed within an organisation, including the purposes for processing and the types of data involved. Keeping a ROPA is compulsory for organisations that regularly process personal data, particularly when the processing is not occasional, involves sensitive information, or could pose a risk to individuals’ rights and freedoms.
The primary purpose of a ROPA is to provide a clear overview of all personal data processing activities within an organisation. It also ensures GDPR compliance by making these activities transparent and traceable. In addition, it supports communication with supervisory authorities by offering detailed documentation, particularly in the event of an audit or investigation.
You can find a guideline on to create and maintain a ROPA in the Data Protection Handbook; additionnaly you can find a template here. If you have any further questions, please feel free to get in touch with dataprotection@elsa.org.
A privacy policy is a formal document that describes how an organisation collects, uses, stores, and protects personal data. It informs individuals about what data is processed, why it is processed, and what rights they have in relation to it. Its main purpose is to ensure transparency and to build trust between ELSA and its members.
Organisations are required to provide clear and easily accessible information about their data processing activities. This includes explaining the purposes and legal bases for processing, identifying data recipients, outlining retention periods, and describing how individuals can exercise their rights. The policy must also set out how personal data is protected and provide contact details for any questions or complaints.
A privacy policy consists of two parts: a summary section that provides a general overview, and a detailed section that explains all data processing activities in depth.
Summary section:
Who we are
Personal data we process
Purposes of the processing
your rights
Detailed section:
1. About us
2. Personal data collection
a. Categories of personal data collected
b. How we collect personal data
3. Legal basis and purposes
4. Data retention
5. Data transfers and sharing
a. Data recipients
b. Third-country and international organisations transfers
c. Data disclosure
6. Data security
7. Your rights
8. Changes to the privacy policy
9. Contact us
For guidance, please feel free to take a look at the templates provided by ELSA International on the Officers' Portal.
A personal data breach occurs when personal data is accidentally lost, destroyed, altered, or disclosed, when it is accessed or shared without proper authorisation, or when it becomes unavailable in a way that has a significant adverse impact on individuals.
Organisations are required to put in place appropriate technical and organisational measures to prevent data breaches as far as possible. Nevertheless, such breaches can still occur at any time. To be prepared for that, you should first of all be able to recognise a personal data breach, understanding that it is not limited to data loss or theft. A clear response plan should be in place, with responsibility assigned to a specific person or team. Processors must know who to contact within the controller’s organisation, and officers should be aware of how to escalate potential incidents appropriately. Additionally, a data breach response policy, outlining its purpose and procedures, should be established.
For more detailed instructions on how to draw up a detailed plan, please read the relevant section in the Data Protection Handbook and feel free to contact dataprotection@elsa.org.